← back
CVE-2023-28503

Authentication bypass in UniRPC's udadmin service

CVSS 9.8 CRITICALEPSS 62.1%CWE-798
In short

A hardcoded username and password in UniData and UniVerse databases allow attackers to bypass login security and run commands with root privileges, completely compromising the system.

Technical detail

CWE-798 hardcoded credentials vulnerability in the udadmin service permits unauthenticated remote attackers to bypass authentication using a predetermined username-password pair and execute arbitrary OS commands with root-level privileges. Affected versions are UniData <8.2.4 build 3003 and UniVerse <11.3.5 build 1001 or <12.2.1 build 2002.

Summary generated and translated by AI from the official description.
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →